logo

Microsoft Defender for Endpoint Internal 0x06 — Custom Collection

ID: d485413b-be88-5dd9-97b7-d0d921085f40

STIX ID: report--d485413b-be88-5dd9-97b7-d0d921085f40

Feed Name: FalconForce

Date Published: 2025-11-20

Date Updated: 2026-06-15

Author: Olaf Hartong

...
...

Microsoft Defender for Endpoint's Custom Collection lets teams define fine-grained telemetry rules that forward uncapped (subject to a 25k/day per-rule/device cap) event streams to Azure Sentinel as DeviceCustom* tables, providing an alternative to adding Sysmon or other agents. The article explains supported tables, licensing and agent requirements (Defender P2, Sentinel workspace, client v10.8805+), cost and operational considerations, and introduces TelemetryCollectionManager — a YAML-based Go tool to validate, deploy, export and manage rules (currently requiring a user token) with guidance to maintain rules in Git for versioning and review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.